IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Aggressive polymorphic malware doubles in July

Symantec says we should all look out for polymorphic malware, but its rise may not be sustained.

Malware

Cyber criminals were increasingly aggressive with their targeted attacks in July, upping their use of polymorphic malware.

Of all email-borne malware samples intercepted by Symantec in July, 23.7 per cent were what the security giant described as "aggressively unstable or rapidly changing forms of generic polymorphic malware."

This was more than double the same figure six months ago - an "alarming proliferation in such a short time," according to Symantec.

This kind of malware has been typically found inside an executable within an attached ZIP file disguised as a PDF file.

Polymorphic malware is particularly good at bypassing traditional anti-virus software.

"The most recent samples were specifically designed to evade detection by software emulators that often form part of the anti-virus engine installed on a target PC. Software emulation is designed to analyse the code and follow the flow of instructions, but only up to a point," the Symantec report read.

"One design element of this new breed of malware includes a series of unnecessary jump' instructions in the start-up code, which are introduced in between the real instructions specifically to confound the anti-virus engine detection."

Many have pointed to the risks of relying too heavily on anti-virus to protect an organisation.

Martin Lee, senior software engineer at Symantec, called on anti-virus providers to develop their products in line with cyber criminal innovation.

"There are powerful Darwinian forces acting on the development of malware by criminals," Lee told IT Pro.

"Those whose malware is easily detectable fail to infect computers, and fail to thrive in the cyber crime environment. On the other hand, those who look to innovate and improve' their malware, tend to infect more computers and acquire the resources to reinvest in further development and innovation."

As for whether the rise of aggressive, polymorphic malware will be sustained, Lee was unsure.

"Malware innovation and development never runs backwards. If the malware writers have mastered how to deploy polymorphic techniques and this provides clear benefits to the distribution of malware, then we will certainly see more of this technique used in the malware in circulation," he added.

"On the other hand, if it less successful than the malware writers hoped, and it proves difficult to use in practice, then we may not see the technique sustained. It's early days, we need to wait and see."

Featured Resources

Meeting the future of education with confidence

How the switch to digital learning has created an opportunity to meet the needs of every student, always

Free Download

The Total Economic Impact™ of IBM Cloud Pak® for Watson AIOps with Instana

Cost savings and business benefits

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

Technology reimagined

Why PCaaS is perfect for modern schools

Free Download

Recommended

Hackers could use new Wslink malware in highly targeted cyber attacks
malware

Hackers could use new Wslink malware in highly targeted cyber attacks

1 Nov 2021
FBI raids Chinese POS business following cyber attack claims
malware

FBI raids Chinese POS business following cyber attack claims

27 Oct 2021
Malware developers create malformed code signatures to avoid detection
malware

Malware developers create malformed code signatures to avoid detection

24 Sep 2021
New malware uses search engine ads to target pirate gamers
malware

New malware uses search engine ads to target pirate gamers

21 Jul 2021

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

7 Jun 2022
Attracting and retaining talent through training
Sponsored

Attracting and retaining talent through training

13 Jun 2022
Delivery firm Yodel disrupted by cyber attack
cyber attacks

Delivery firm Yodel disrupted by cyber attack

21 Jun 2022